Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28756

Опубликовано: 31 мар. 2023
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
Версия до 2.7.7 (включая)
cpe:2.3:a:ruby-lang:time:0.1.0:*:*:*:*:ruby:*:*
cpe:2.3:a:ruby-lang:time:0.2.1:*:*:*:*:ruby:*:*
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

EPSS

Процентиль: 70%
0.00665
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.

CVSS3: 5.3
redhat
около 2 лет назад

A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.

CVSS3: 5.3
debian
около 2 лет назад

A ReDoS issue was discovered in the Time component through 0.2.1 in Ru ...

CVSS3: 7.5
github
около 2 лет назад

Ruby Time component ReDoS issue

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость библиотеки Time интерпретатора Ruby, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 70%
0.00665
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-1333